Hi Team
We are planning to conduct a PT on the application, we have requested by the vendor to validate the attachments and make sure the attachments not vulnerable. Also, they request us to scan the files with antivirus scanning services.
Any recommendations here ?
3 Answer(s)
-
0
Hi @smartech
ASP.NET Zero provides a multi layer file upload validation mechanism to reduce risks related to malicious attachments. The built in file validation pipeline includes:
Extension Whitelisting Only explicitly allowed file extensions can be uploaded.
MIME Type Validation Uploaded files are validated against their declared Content Type.
File Size Limits Configurable maximum size restrictions are enforced per file upload.
Supported file categories typically include images, documents, and text based files, depending on application configuration.
Antivirus Scanning
ASP.NET Zero does not include antivirus scanning by default, as scanning strategies depend heavily on infrastructure and compliance requirements. However, the upload pipeline is designed to be extensible, and antivirus scanning can be integrated before persistence of the file.
Commonly used and supported integration approaches include:
- ClamAV (self hosted or container based scanning)
- Windows Defender (for on premise Windows environments)
- Cloud based services such as VirusTotal API or Azure Defender for Storage
- Custom ICAP based scanning services
A recommended approach is to block file persistence until the scan completes and reject uploads flagged as malicious.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
How you are testing the PDF files contains malicious code ?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @smartech
ASP.NET Zero’s built in PdfFileValidator performs structural validation on uploaded PDF files. This validation includes:
Extension validation Only
.pdffiles are accepted.MIME type validation Verifies that the uploaded file declares the
application/pdfcontent type.Magic bytes (file signature) validation Ensures the file starts with the
%PDFheader (0x25 0x50 0x44 0x46).
These checks confirm that the uploaded file is a valid PDF file structurally. However, they do not detect malicious payloads embedded inside a valid PDF, such as:
- Embedded JavaScript
- Launch Actions
- Embedded executables
- Exploit code targeting PDF reader vulnerabilities
Detection of such threats requires antivirus or sandbox based scanning.
Malicious Content Detection
For advanced malicious content detection, one of the following integrations is recommended:
| Approach | Description | | ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------- | | ClamAV | Open source antivirus engine. Can be self hosted or containerized. For .NET integration, the
nClamNuGet package can be used. | | Windows Defender / AMSI | Suitable for on premise Windows environments. Files can be scanned via the Anti Malware Scan Interface (AMSI). | | VirusTotal API | Cloud based scanning using 70+ antivirus engines. Recommended for low volume uploads. | | Azure Defender for Storage | If Azure Blob Storage is used, uploaded files are automatically scanned. |Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)